Skip to main content
Sign in

Audit log

Every state-changing event for Harmony ONE (August 2026 Layer-1 mint exploit): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-30 12:14:01Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    65VoqtkbYQdR…QJZTve31sha256 → base58
    verifying row…
    canonical bytes (20253 B) ▸
    {"actor":"system:backfill","investigation_id":"a56e663a-d007-4dbb-ba10-07e27f706ebd","kind":"publish","page_slug":"harmony-one-august-2026-layer-1-mint-exploit","published_at":"2026-08-30T12:14:01.810Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Harmony ONE (August 2026 Layer-1 mint exploit)","sections":[{"content":"On August 12, 2026, at approximately 23:25:40 UTC on August 11 (block 92,730,036 on Shard 0), an attacker began exploiting two consensus-layer vulnerabilities in Harmony's mainnet to issue unauthorized ONE tokens. The attacker executed at least two minting events: 1 billion ONE at block 92,731,152 (00:02:59 UTC, August 12) and 3 billion ONE at block 92,732,898 (01:01:17 UTC, August 12). On-chain analysis by independent researcher Juiceberg estimated that approximately 97% of the minted tokens reached exchange deposit wallets before any freeze could take effect. The token's price fell between 30% and 40% intraday to roughly $0.0008, an all-time low, with market capitalization falling to approximately $10.6–11.5 million. An independent analyst publicly flagged the anomaly before Harmony's official acknowledgment. The totalSupply endpoint failed to reflect the minted tokens during the critical early window, delaying detection by exchanges and dashboards.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":1,"name":"CoinDesk — Harmony's ONE falls 40% after attacker allegedly mints 4 billion tokens","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"credibility":1,"name":"Harmony Protocol — Incident Update: August 13, 2026 (official X post)","type":"official","url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"credibility":2,"name":"TechTimes — Harmony ONE Hacked: 4 Billion Tokens Minted, Supply Masking Sent 97% to Exchanges","type":"news_article","url":"https://www.techtimes.com/articles/324068/20260812/harmony-one-hacked-4-billion-tokens-minted-supply-masking-sent-97-exchanges.htm"},{"credibility":2,"name":"DeFiMon — Harmony Hack: 4 Billion ONE Minted in Supply Exploit (2026)","type":"research","url":"https://defimon.xyz/blog/harmony-hack-august-2026"}]},{"content":"Harmony's official incident update and independent security researchers identified two distinct consensus-layer vulnerabilities that were chained in the attack. The first was a pre-staking quorum verification flaw: the consensus code counted every public key listed in a signature mask rather than the validators who had actually signed the message. An empty signer bitmap paired with a mathematically neutral (identity) aggregate BLS signature was sufficient to pass quorum checks, meaning transactions with zero valid signatures could be accepted by the network. The second vulnerability was a cross-shard receipt replay flaw: certain proof fields in cross-shard receipts were not cryptographically bound to the signed block header, allowing a previously processed receipt to be presented as new, thereby enabling double-crediting of tokens without corresponding debits. The combination allowed the attacker to manufacture 'empty block' credits that directly minted fresh ONE tokens to attacker-controlled wallets. One wallet alone reportedly pushed 2.385 trillion forged ONE through 477 transfers in approximately 106 seconds according to on-chain reconstruction reported by DeFiMon. The totalSupply endpoint did not immediately reflect the minted tokens, masking the supply inflation from monitoring tools during the critical window.","heading":"Technical Root Cause","severity":"critical","sources":[{"credibility":1,"name":"Harmony Protocol — Incident Update: August 13, 2026 (official X post)","type":"official","url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"credibility":2,"name":"Lookonchain — Harmony Releases Probe Results: Confirms 4 Billion ONE Tokens Minted, Vulnerability Fixed, Rollback Prepared","type":"on_chain","url":"https://www.lookonchain.com/feeds/68301"},{"credibility":2,"name":"DeFiMon — Harmony Hack: 4 Billion ONE Minted in Supply Exploit (2026)","type":"research","url":"https://defimon.xyz/blog/harmony-hack-august-2026"},{"credibility":2,"name":"CryptoSlate — Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges","type":"news_article","url":"https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/"}]},{"content":"The ONE token price fell between 30% and 40% intraday on August 12, 2026, reaching approximately $0.0008, described by multiple outlets as an all-time low. Market capitalization dropped to an estimated $10.6–11.5 million. The token ranked outside the top 1,000 cryptocurrencies by market cap following the crash. The value of the 4 billion minted tokens at post-crash prices was estimated at roughly $3.2 million. Longer-term price context shows ONE had already declined approximately 36% over the prior 30 days and 62% over the prior 90 days before the exploit occurred.","heading":"Market Impact","severity":"high","sources":[{"credibility":1,"name":"CoinDesk — Harmony's ONE falls 40% after attacker allegedly mints 4 billion tokens","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"credibility":1,"name":"Yahoo Finance — Harmony Will Delete Nearly a Week of Its Own Chain History","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/harmony-delete-nearly-week-own-064216020.html"},{"credibility":2,"name":"DeFiMon — Harmony Hack: 4 Billion ONE Minted in Supply Exploit (2026)","type":"research","url":"https://defimon.xyz/blog/harmony-hack-august-2026"}]},{"content":"Harmony deployed emergency patch Mainnet v2026.1.1 (pull request #5101) at approximately 06:30 UTC on August 12, 2026 — roughly five hours after the first unauthorized mint and approximately 65 minutes after the exploit became public. The patch addressed both the pre-staking quorum verification flaw and the cross-shard receipt replay vulnerability. Harmony simultaneously suspended bridge.harmony.one. The team published four attacker wallet addresses and coordinated with centralized exchanges and the cross-chain messaging protocol LayerZero to freeze or block traceable funds. Shard 0 was halted at block 92,753,555 as part of the containment effort. According to reporting, approximately 97% of the minted tokens had already reached exchange deposit wallets before freezes could take effect, significantly limiting the effectiveness of post-exploit fund recovery.","heading":"Emergency Response and Patch","severity":"medium","sources":[{"credibility":1,"name":"Harmony Protocol — Incident Update: August 13, 2026 (official X post)","type":"official","url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"credibility":2,"name":"Lookonchain — Harmony Releases Probe Results: Confirms 4 Billion ONE Tokens Minted","type":"on_chain","url":"https://www.lookonchain.com/feeds/68301"},{"credibility":2,"name":"Coin360 — Harmony ONE Mint Triggers Patch, Exchange Freeze Push","type":"news_article","url":"https://coin360.com/news/harmony-one-unauthorized-mint-emergency-patch"},{"credibility":2,"name":"KuCoin — Harmony Protocol Confirms 4 Billion ONE Minted in Unauthorized Attack, Prepares Network Rollback","type":"news_article","url":"https://www.kucoin.com/news/flash/harmony-protocol-confirms-4-billion-one-minted-in-unauthorized-attack-prepares-network-rollback"}]},{"content":"Faced with the scale of unauthorized token issuance and the limited effectiveness of exchange-level freezes, Harmony's team proposed a full blockchain rollback to the pre-exploit state. The rollback target was block 92,730,034 on Shard 0 and block 94,978,278 on Shard 1, both corresponding to the chain state at 23:25:37 UTC on August 11, 2026, shortly before the first confirmed forged mint. Harmony confirmed the rollback on approximately August 17–18, 2026. Validators received new databases, and the network resumed operations from blocks #92,730,035 and #94,978,279 respectively. A second stage of the rollback procedure was activated on approximately August 20, 2026. Post-rollback, both shards were reported stable for 24+ hours, producing approximately 100,000 blocks and advancing from epoch 3002 to 3004 with near-full validator signing participation. The rollback erased an estimated 109,126 regular and 315 staking transactions — approximately 96% of which were reported to be automated DEX activity. The rollback raised questions about blockchain finality and decentralization, as noted by CrowdFund Insider, since it required coordinated action among validators to unilaterally reverse confirmed blocks.","heading":"Blockchain Rollback","severity":"high","sources":[{"credibility":1,"name":"Yahoo Finance — Harmony Will Delete Nearly a Week of Its Own Chain History","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/harmony-delete-nearly-week-own-064216020.html"},{"credibility":2,"name":"Forklog — Harmony to Roll Back Blockchain After Attack Issuing Trillions of ONE","type":"news_article","url":"https://forklog.com/en/harmony-to-roll-back-blockchain-after-attack-issuing-trillions-of-one/"},{"credibility":1,"name":"Harmony Protocol — Incident Update: August 13, 2026 (official X post)","type":"official","url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"credibility":2,"name":"CrowdFund Insider — Harmony Protocol Plans Network Rollback, Raising Blockchain Immutability and Decentralization Concerns","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/298395-harmony-protocol-plans-network-rollback-after-token-forgery-exploit-raising-blockchain-immutability-and-lack-of-decentralization-concerns/"},{"credibility":2,"name":"Crypto.news — Harmony plans chain rollback as forged ONE spreads across network","type":"news_article","url":"https://crypto.news/harmony-plans-chain-rollback-as-forged-one-spreads-across-network/"},{"credibility":2,"name":"DeFiMon — Harmony Hack: 4 Billion ONE Minted in Supply Exploit (2026)","type":"research","url":"https://defimon.xyz/blog/harmony-hack-august-2026"}]},{"content":"As of the time of this writing, the attacker's identity has not been publicly confirmed or attributed by Harmony, law enforcement, or any independent security researcher. Harmony published four wallet addresses associated with the exploit and shared these with exchanges and LayerZero for freezing purposes: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn (0xe7427699427821230177dd13f460d6ce43014510) and one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4 (0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5). No law enforcement action or formal criminal referral has been publicly announced as of this writing.","heading":"Attacker Identity and Wallet Addresses","severity":"high","sources":[{"credibility":1,"name":"Harmony Protocol — Incident Update: August 13, 2026 (official X post)","type":"official","url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"credibility":2,"name":"DeFiMon — Harmony Hack: 4 Billion ONE Minted in Supply Exploit (2026)","type":"research","url":"https://defimon.xyz/blog/harmony-hack-august-2026"}]},{"content":"This August 2026 incident is distinct from the June 2022 Horizon bridge hack, in which approximately $100 million in assets were drained from Harmony's cross-chain bridge through a private key compromise. The 2026 exploit targeted a different attack surface — the Layer-1 consensus and cross-shard receipt validation mechanisms — rather than the bridge's key management. The two events represent separate vulnerabilities and separate incidents. CryptoSlate and other outlets reference the 2022 event as comparative context for Harmony's history of security incidents.","heading":"Distinction from 2022 Horizon Bridge Hack","severity":"low","sources":[{"credibility":2,"name":"CryptoSlate — Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges","type":"news_article","url":"https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/"}]},{"content":"Several material facts remain unconfirmed or contested as of this writing. The total amount of tokens frozen at exchanges has not been publicly confirmed by Harmony or any exchange. The exact net financial loss to token holders from the exploit (after the rollback) is unclear, given that the rollback reversed most on-chain state changes. The rollback's treatment of exchange-deposited tokens — which settled on external systems outside Harmony's chain state — has not been fully documented publicly. No independent security audit of the patch has been published. No law enforcement investigation has been publicly announced.","heading":"Unresolved Questions","severity":"medium","sources":[{"credibility":2,"name":"CryptoSlate — Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges","type":"news_article","url":"https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/"},{"credibility":1,"name":"Yahoo Finance — Harmony Will Delete Nearly a Week of Its Own Chain History","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/harmony-delete-nearly-week-own-064216020.html"}]}],"sources_used":[{"credibility":1,"name":"CoinDesk — Harmony's ONE falls 40% after attacker allegedly mints 4 billion tokens","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"credibility":1,"name":"Harmony Protocol — Incident Update: August 13, 2026 (official X post)","type":"official","url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"credibility":1,"name":"Yahoo Finance — Harmony Will Delete Nearly a Week of Its Own Chain History","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/harmony-delete-nearly-week-own-064216020.html"},{"credibility":2,"name":"Lookonchain — Harmony Releases Probe Results: Confirms 4 Billion ONE Tokens Minted, Vulnerability Fixed, Rollback Prepared","type":"on_chain","url":"https://www.lookonchain.com/feeds/68301"},{"credibility":2,"name":"CryptoSlate — Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges","type":"news_article","url":"https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/"},{"credibility":2,"name":"DeFiMon — Harmony Hack: 4 Billion ONE Minted in Supply Exploit (2026)","type":"research","url":"https://defimon.xyz/blog/harmony-hack-august-2026"},{"credibility":2,"name":"TechTimes — Harmony ONE Hacked: 4 Billion Tokens Minted, Supply Masking Sent 97% to Exchanges","type":"news_article","url":"https://www.techtimes.com/articles/324068/20260812/harmony-one-hacked-4-billion-tokens-minted-supply-masking-sent-97-exchanges.htm"},{"credibility":2,"name":"Forklog — Harmony to Roll Back Blockchain After Attack Issuing Trillions of ONE","type":"news_article","url":"https://forklog.com/en/harmony-to-roll-back-blockchain-after-attack-issuing-trillions-of-one/"},{"credibility":2,"name":"CrowdFund Insider — Harmony Protocol Plans Network Rollback, Raising Blockchain Immutability and Decentralization Concerns","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/298395-harmony-protocol-plans-network-rollback-after-token-forgery-exploit-raising-blockchain-immutability-and-lack-of-decentralization-concerns/"},{"credibility":2,"name":"KuCoin — Harmony Protocol Confirms 4 Billion ONE Minted in Unauthorized Attack, Prepares Network Rollback","type":"news_article","url":"https://www.kucoin.com/news/flash/harmony-protocol-confirms-4-billion-one-minted-in-unauthorized-attack-prepares-network-rollback"},{"credibility":2,"name":"Coin360 — Harmony ONE Mint Triggers Patch, Exchange Freeze Push","type":"news_article","url":"https://coin360.com/news/harmony-one-unauthorized-mint-emergency-patch"},{"credibility":2,"name":"Crypto.news — Harmony plans chain rollback as forged ONE spreads across network","type":"news_article","url":"https://crypto.news/harmony-plans-chain-rollback-as-forged-one-spreads-across-network/"},{"credibility":2,"name":"Halborn — Explained: The Harmony Hack August 2026","type":"research","url":"https://www.halborn.com/blog/post/explained-the-harmony-hack-august-2026"}],"summary":"On August 12, 2026, an unidentified attacker exploited two consensus-layer vulnerabilities in the Harmony ONE mainnet to mint approximately 4 billion unauthorized ONE tokens, inflating the circulating supply by roughly 26%. Approximately 97% of the minted tokens reached cryptocurrency exchange deposit wallets before freezes could be enacted. Harmony deployed an emergency patch within roughly five hours, suspended its cross-chain bridge, and subsequently executed a full blockchain rollback to the pre-exploit state of August 11, 2026, erasing more than 109,000 legitimate transactions in the process. This incident is distinct from the June 2022 Horizon bridge hack.","timeline":[{"date":"2026-08-11","event":"Attacker begins exploit activity on Shard 0 at approximately 23:25:40 UTC (block 92,730,036); first forged mint at block 92,731,152 (1 billion ONE, 00:02:59 UTC).","source":"Harmony Protocol official incident update (X post, August 13, 2026)","source_url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"date":"2026-08-12","event":"Second mint of 3 billion ONE at block 92,732,898 (01:01:17 UTC). Approximately 2.8 billion ONE transferred at 01:02:31 UTC; nearly all moved by 01:05:24 UTC. ~97% of minted tokens reach exchange deposit addresses before any freeze.","source":"Harmony Protocol official incident update; Lookonchain on-chain analysis","source_url":"https://www.lookonchain.com/feeds/68301"},{"date":"2026-08-12","event":"Independent analyst publicly flags the unauthorized minting anomaly before Harmony's official acknowledgment. ONE price drops 30–40% intraday to roughly $0.0008.","source":"CoinDesk; DeFiMon","source_url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"date":"2026-08-12","event":"Emergency patch Mainnet v2026.1.1 (PR #5101) deployed at approximately 06:30 UTC, patching both the quorum verification flaw and the cross-shard receipt replay vulnerability. Bridge.harmony.one suspended. Shard 0 halted at block 92,753,555.","source":"Harmony Protocol official incident update (X post)","source_url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"date":"2026-08-13","event":"Harmony publishes formal incident update on X, discloses four attacker wallet addresses, confirms coordination with exchanges and LayerZero for fund freezing.","source":"Harmony Protocol official incident update (X post)","source_url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"date":"2026-08-17","event":"Harmony formally proposes a full blockchain rollback targeting Shard 0 block 92,730,034 and Shard 1 block 94,978,278 (both at 23:25:37 UTC, August 11). Rollback would erase approximately 109,126 regular and 315 staking transactions.","source":"DeFiMon; Cryptonomist","source_url":"https://defimon.xyz/blog/harmony-hack-august-2026"},{"date":"2026-08-18","event":"Harmony confirms rollback execution. Validators receive new databases; network resumes from blocks #92,730,035 (Shard 0) and #94,978,279 (Shard 1).","source":"Forklog; Yahoo Finance","source_url":"https://forklog.com/en/harmony-to-roll-back-blockchain-after-attack-issuing-trillions-of-one/"},{"date":"2026-08-20","event":"Validators activate second stage of rollback procedure. Both shards reported stable for 24+ hours with near-full signing participation, advancing from epoch 3002 to 3004.","source":"CoinMarketCap AI — Latest Harmony News (August 2026)","source_url":"https://coinmarketcap.com/cmc-ai/harmony/latest-updates/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 5897a9ab-5422-4bac-ab77-b926186439cd
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.